Oracle Solaris vulnerabilities
551 known vulnerabilities affecting oracle/solaris.
Total CVEs
551
CISA KEV
6
actively exploited
Public exploits
29
Exploited in wild
10
Severity breakdown
CRITICAL46HIGH116MEDIUM286LOW103
Vulnerabilities
Page 6 of 28
CVE-2018-2926P3HIGHCVSS 7.6v11.32018-07-18
CVE-2018-2926 [HIGH] CVE-2018-2926: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: NVIDIA-GF
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: NVIDIA-GFX Kernel driver). The supported version that is affected is 11.3. Easily exploitable vulnerability allows low privileged attacker with network access via ISCSI to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized ability to c
nvd
CVE-2013-5610P3CRITICALCVSS 10.0v11.32013-12-11
CVE-2013-5610 [CRITICAL] CWE-787 CVE-2013-5610: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 26.0 and SeaMon
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2014-6052P3HIGHCVSS 7.5v11.32014-12-15
CVE-2014-6052 [HIGH] CWE-20 CVE-2014-6052: The HandleRFBServerMessage function in libvncclient/rfbproto.c in LibVNCServer 0.9.9 and earlier doe
The HandleRFBServerMessage function in libvncclient/rfbproto.c in LibVNCServer 0.9.9 and earlier does not check certain malloc return values, which allows remote VNC servers to cause a denial of service (application crash) or possibly execute arbitrary code by specifying a large screen size in a (1) FramebufferUpdate, (2) ResizeFrameBuffer, or (3) PalmVN
nvd
CVE-2015-2740P3CRITICALCVSS 10.0v11.32015-07-06
CVE-2015-2740 [CRITICAL] CWE-119 CVE-2015-2740: Buffer overflow in the nsXMLHttpRequest::AppendToResponseText function in Mozilla Firefox before 39.
Buffer overflow in the nsXMLHttpRequest::AppendToResponseText function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 might allow remote attackers to cause a denial of service or have unspecified other impact via unknown vectors.
nvd
CVE-2015-4492P3HIGHCVSS 7.5v11.32015-08-16
CVE-2015-4492 [HIGH] CVE-2015-4492: Use-after-free vulnerability in the XMLHttpRequest::Open implementation in Mozilla Firefox before 40
Use-after-free vulnerability in the XMLHttpRequest::Open implementation in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 might allow remote attackers to execute arbitrary code via a SharedWorker object that makes recursive calls to the open method of an XMLHttpRequest object.
nvd
CVE-2015-2743P3HIGHCVSS 7.5v11.32015-07-06
CVE-2015-2743 [HIGH] CWE-17 CVE-2015-2743: PDF.js in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 enables
PDF.js in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 enables excessive privileges for internal Workers, which might allow remote attackers to execute arbitrary code by leveraging a Same Origin Policy bypass.
nvd
CVE-2018-2710P3HIGHCVSS 7.5v10.02018-01-18
CVE-2018-2710 [HIGH] CVE-2018-2710: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel).
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 10. Easily exploitable vulnerability allows unauthenticated attacker with network access via ICMP to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or freque
nvd
CVE-2001-0249P3CRITICALCVSS 9.8v82001-06-18
CVE-2001-0249 [CRITICAL] CWE-131 CVE-2001-0249: Heap overflow in FTP daemon in Solaris 8 allows remote attackers to execute arbitrary commands by cr
Heap overflow in FTP daemon in Solaris 8 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the LIST command, which uses glob to generate long strings.
nvd
CVE-2022-21514P3HIGHCVSS 7.5v112022-07-19
CVE-2022-21514 [HIGH] CVE-2022-21514: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Remote Administration Daem
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Remote Administration Daemon). The supported version that is affected is 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized abil
nvd
CVE-2017-3497P3HIGHCVSS 7.3v11.32017-04-24
CVE-2017-3497 [HIGH] CVE-2017-3497: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Remote Ad
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Remote Administration Daemon). The supported version that is affected is 11.3. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Solaris. Successful attacks of this vulnerability can result in unaut
nvd
CVE-2016-5842P3HIGHCVSS 7.5v10v11.32016-12-13
CVE-2016-5842 [HIGH] CWE-125 CVE-2016-5842: MagickCore/property.c in ImageMagick before 7.0.2-1 allows remote attackers to obtain sensitive memo
MagickCore/property.c in ImageMagick before 7.0.2-1 allows remote attackers to obtain sensitive memory information via vectors involving the q variable, which triggers an out-of-bounds read.
nvd
CVE-2015-7236P3HIGHCVSS 7.5v10v11.32015-10-01
CVE-2015-7236 [HIGH] CVE-2015-7236: Use-after-free vulnerability in xprt_set_caller in rpcb_svc_com.c in rpcbind 0.2.1 and earlier allow
Use-after-free vulnerability in xprt_set_caller in rpcb_svc_com.c in rpcbind 0.2.1 and earlier allows remote attackers to cause a denial of service (daemon crash) via crafted packets, involving a PMAP_CALLIT code.
nvd
CVE-2015-2726P3CRITICALCVSS 10.0v11.32015-07-06
CVE-2015-2726 [CRITICAL] CWE-119 CVE-2015-2726: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0 allow remo
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2015-2724P3CRITICALCVSS 10.0v11.32015-07-06
CVE-2015-2724 [CRITICAL] CWE-119 CVE-2015-2724: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2014-9674P3HIGHCVSS 7.5v10.0v11.22015-02-08
CVE-2014-9674 [HIGH] CVE-2014-9674: The Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 proceeds with adding t
The Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 proceeds with adding to length values without validating the original values, which allows remote attackers to cause a denial of service (integer overflow and heap-based buffer overflow) or possibly have unspecified other impact via a crafted Mac font.
nvd
CVE-2014-7142P3MEDIUMCVSS 6.4v11.22014-11-26
CVE-2014-7142 [MEDIUM] CWE-20 CVE-2014-7142: The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or caus
The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (crash) via a crafted (1) ICMP or (2) ICMP6 packet size.
nvd
CVE-2018-2908P3HIGHCVSS 7.7v11.32018-07-18
CVE-2018-2908 [HIGH] CVE-2018-2908: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel).
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11.3. Easily exploitable vulnerability allows low privileged attacker with network access via RPC to compromise Solaris. While the vulnerability is in Solaris, attacks may significantly impact additional products. Successf
nvd
CVE-2015-2736P3CRITICALCVSS 9.3v11.32015-07-06
CVE-2015-2736 [CRITICAL] CWE-17 CVE-2015-2736: The nsZipArchive::BuildFileList function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.
The nsZipArchive::BuildFileList function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 accesses unintended memory locations, which allows remote attackers to have an unspecified impact via a crafted ZIP archive.
nvd
CVE-2023-21948P3HIGHCVSS 7.8v102023-04-18
CVE-2023-21948 [HIGH] CVE-2023-21948: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Core). The supported ver
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Core). The supported version that is affected is 10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in takeover of Oracle Solar
nvd
CVE-2023-22023P3HIGHCVSS 7.8v112023-07-18
CVE-2023-22023 [HIGH] CWE-269 CVE-2023-22023: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Device Driver Interface).
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Device Driver Interface). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result
nvd